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Top Stories 

• Between 1,500 - 2,000 patrons who dined at the Casa-di-Pizza restaurant in Buffalo, New 
York, from March 9-19 were encouraged to obtain a hepatitis A vaccination after an 
employee was diagnosed with the illness March 20. - Buffalo News (See item 11 ) 

• Amy’s Kitchen, Inc., issued a recall for about 73,897 cases of various products after a 
supplier notified the company that it may have received organic spinach with the possible 
presence of Listeria monocytogenes- U.S. Food and Drug Administration (See item 14 ) 

• A Pentagon spokesperson reported March 23 that U.S. military units notified members 
whose names and addresses were included on a “kill list” allegedly created by the Islamic 
State Hacking Division, who claim to be sympathizers of the Islamic State terrorist group. 
- USA Today (See item 21 ) 

• Three subcontractors were killed and a fourth was injured March 23 when a track snapped 
while the workers were dismantling a scaffold on the exterior of a Raleigh, North Carolina 
high rise and the men fell about 200 feet to the ground. - WSOC 9 Charlotte (See item 33 ) 
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Energy Sector 



1. March 23, WYMT 57 Hazard - (West Virginia) Patriot Coal idles two mines in West 
Virginia. Patriot Coal announced March 23 that coal production at its Paint Creek 
Complex facility in West Virginia was idled effective March 22 due to a lesser demand 
for coal and high inventory levels. Coal production is scheduled to resume in 3 - 4 
weeks while processing and shipping of coal to customers from stockpiles will 
continue. 

Source: http://www.wkvt.com/wvmt/home/headlines/Patriot-Coal-idles-two-rnines-in- 
West-Virginia-29728098 1 .html 

[ Return to top ] 

Chemical Industry Sector 

2. March 23, Associated Press - (West Virginia) Freedom Industries pleads guilty to 
pollution charges in West Virginia chemical spill case. Now-bankrupt Freedom 
Industries pleaded guilty in federal court March 23 to 3 pollution charges related to a 
January 2014 chemical spill from the company’s Charleston, West Virginia facility into 
the Elk River which contaminated the water supply of 300,000 individuals. 

Source: http://www.foxnews.com/us/2015/03/23/freedom-industries-pleads-guilty-to- 
pollution-charges-in-west- virginia-chemical/ 

[ Return to top ] 

Nuclear Reactors, Materials, and Waste Sector 

Nothing to report 
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Critical Manufacturing Sector 

3. March 23, Warren Reporter - (New Jersey) Toxic product fire at Warren County 
company sends 5 to hospital. Five workers at the Witte Company in Washington 
Township, New Jersey, were hospitalized and 18 others reported respiratory problems 
following a March 23 fire that involved a toxic organic product and prompted a 
HAZMAT response. Officials inspected the site and a cleanup company was hired to 
manage the incident. 

Source: 

http://www.ni.com/warrenreporter/index.ssf/2015/03/toxic product fire at warren c.h 
tml 

[ Return to top i 



Defense Industrial Base Sector 
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Nothing to report 
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Financial Services Sector 

4. March 24, KrebsOnSecurity - (International) Kreditech investigates insider breach. 
Germany-based Kreditech is working with authorities to investigate a November 2014 
internal isolated security incident where an apparent insider breach of its systems 
occurred and information from credit applicants was taken. The company stated that no 
customer data was breached from the event which originated from a form on its official 
Web site that stored data in a caching system which deleted data every few days. 
Source: http://krebsonsecurity.com/2015/03/kreditech-investigates-insider-breach/ 

5. March 23, Securityweek - (International) Phishers leverage .gov domain loophole to 
bypass email validation. Security researchers at Trend Micro discovered that 
cybercriminals responsible for a March 4-11 phishing attack that sent over 430,000 
emails targeting American Express customers maximized the attack’s effectiveness by 
exploiting a loophole in the way DomainKeys Identified Mail (DKIM) and Sender 
Policy Framework (SPF) email verification systems handle messages from .gov top- 
level domains (TLDs). 

Source: http://www.securitvweek.com/phishers-leverage-gov-domain-loophole-bypass- 
email-validation 

T Return to top i 

Transportation Systems Sector 

6. March 24, KDVR 31 Denver - (Colorado) Second train derails in Weld County in 
two days. Three cars of a Union Pacific train derailed in Weld County and damaged 
200 feet of track March 23 prompting crews to work overnight to clear the scene and 
make repairs. The line reopened March 24 while authorities continue to investigate the 
cause of the derailment. 

Source: http://kdvr.com/2015/03/24/second-train-derails-in-weld-countv-in-two-days/ 

7. March 24, WHIO 7 Dayton - (Ohio) Woman avoids pileup on 1-75. Northbound lanes 
of Interstate 75 between Routes 119 and 274 in Shelby County were shut down for 
about 2 hours March 23 when snowy conditions caused a chain-reaction pileup that 
involved 15-20 vehicles. Four individuals were transported to area hospitals with non- 
life-threatening injuries. 

Source: http://www.whio.com/news/news/breaking-news/several-car-pile-up-in-shelby- 
county/nkc58/ 

8. March 23, USA Today - (Illinois) Fliers not done with snow; storm slows Chicago 
flights. About 150 flights were canceled at O’Hare International Airport in Chicago 
March 23 due to a winter storm that moved through the area and was expected to dump 
up to 5 inches of snow. 
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Source: http://www.usatodav.com/storv/todavintheskv/2015/03/23/fliers-not-done- 
with-snow-storms-slows-chicago-flights/252 14263/ 

9. March 23, KPIX 5 San Francisco - (California) Highway 1 reopens in San Mateo 
County after fatal collision. A stretch of Highway 1 near Ano Nuevo State Park in 
San Mateo County was closed in both directions for more than 3 hours March 23 
following a head-on collision that killed 1 person and injured 2 others. 

Source: http://sanfrancisco.cbslocal.com/2015/03/23/highwav-l-reopens-in-san-mateo- 
county-after-fatal-collision/ 

10. March 23, Dickinson Press - (North Dakota) 1 dead, 2 injured after icy roads in 
western N.D. lead to three accidents on 1-94. A portion of eastbound Interstate 94 
near Richardton was shut down for approximately 14 hours March 22 after the roadway 
was blocked by 3 accidents that were caused by icy road conditions. 

Source: http://www.thedickinsonpress.com/news/local/3705660-l-dead-2-iniured-after- 
icy-roads-westem-nd-lead-three-accidents-i-94 
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Food and Agriculture Sector 

11. March 24, Buffalo News - (New York) Casa-di-Pizza management to address 
hepatitis A situation. Between 1,500 and 2,000 patrons who dined at the Casa-di-Pizza 
restaurant in Buffalo from March 9-19 were encouraged to obtain a hepatitis A 
vaccination after an employee was diagnosed with the viral illness March 20. Health 
officials opened a makeshift clinic at the Buffalo Niagara Convention Center where 
patrons can receive the vaccine. 

Source: http://www.buffalonews.com/city-region/communities/casa-di-pizza- 
management-to-address-hepatitis-a-situation-20 150324 

12. March 24, Associated Press - (Connecticut) Connecticut farm worker killed when 
corn collapses on him. A worker at the Square A Farm in Lebanon, Connecticut, was 
killed March 23 after a pile of milled corn collapsed on him as he dismounted from 
equipment that was being used to move the corn. 

Source: http://www.sfgate.com/news/article/Connecticut-farm-worker-killed-when- 
com-6154188.php 

13. March 23, Wilmington News Journal - (Delaware) Rare, destructive bug found in 
bananas at port. U.S. Customs and Border Protection officials confirmed March 23 
that the agency’s agriculture specialists found a leafhopper, an insect from Central and 
South America that is known to damage crops, during an inspection of a shipment of 
bananas from Guatemala to the Port of Wilmington in Delaware. The shipment was 
released to its importer after the inspection was complete. 

Source: http://www.delawareonline.com/storv/news/local/2015/03/23/rare-destructive- 
bug-found-ban anas-port/70332952/ 

14. March 23, U.S. Food and Drug Administration - (International) Amy’s Kitchen 
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recalls various products because of possible health risk. The U S. Food and Drug 
Administration announced March 22 that Amy’s Kitchen, Inc., issued a recall for about 
73,897 cases of various products after a supplier notified the company that it may have 
received organic spinach with the possible presence of Listeria monocytogenes. The 
affected products were sent to retailers across the U.S. and Canada. 

Source: http://www.fda.gov/Safety/Recalls/ucm439397.htm 

15. March 23, U.S. Food and Drug Administration - (National) Wegmans announces 
recall of (frozen) Wegmans Organic Food You Feel Good About Just Picked 
Spinach, 12 oz. which may be contaminated with Listeria monocytogenes. The U.S. 
Food and Drug Administration reported March 23 that Wegmans Food Markets, Inc., 
recalled about 12,540 packages of its Organic Food You Feel Good About Just Picked 
Frozen Spinach due to possible Listeria monocytogenes contamination. The recalled 
product was sold in 12-ounce packages in the frozen food department of 85 Wegmans 
stores across several States. 

Source: http://www.fda.gov/Safety/Recalls/ucm439439.htm 

16. March 23, U.S. Food and Drug Administration - (National) Blue Bell Ice Cream 
recalls 3 oz. institutional/food service ice cream cups - chocolate, strawberry, 
vanilla (tab lid) - because of possible health risk. The U.S. Food and Drug 
Administration reported March 23 that Blue Bell Ice Cream recalled 3-ounce 
institutional/food service ice cream cups sold in chocolate, strawberry, and vanilla 
flavors due to possible Listeria monocytogenes contamination. The recalled products 
were distributed in several States via food service accounts and were not sold through 
retail outlets. 

Source: http://www.fda.gov/Safety/Recalls/ucm439533.htm 
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Water and Wastewater Systems Sector 

17. March 23, WWAY 3 Wilmington - (North Carolina) CFPUA: 4,500 gallons of sewage 
overflows into creek. Water quality testing was underway March 23 following a sewer 
overflow of approximately 4,500 gallons of wastewater that reached a tributary of 
Pages Creek in Wilmington, North Carolina, March 22. The overflow lasted more than 
1 hour and was stopped after crews removed roots that were blocking sewer flow in a 
manhole. 

Source: http://www.wwavtv3.com/2015/03/23/cfpua-4500-gallons-of-sewage- 
overflows-into-creek 
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Healthcare and Public Health Sector 

18. March 23, Reuters - (National) FDA approves Abiomed’s blood pump device. The 
U.S. Food and Drug Administration stated March 23 that it approved Abiomed Inc.’s 
Impella 2.5 System, a miniature blood pump system that can be used during 
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angioplasty and stenting to maintain heart function and circulation during high-risk 
procedures. 

Source: http://www.reuters.com/article/2015/03/23/us-abiomed-fda- 



idUSKBN0MJ2D0201 50323 



For another story, see item 11 
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Government Facilities Sector 

19. March 24, Fredericksburg Free Lance-Star - (Virginia) School bus accident in 
Spotsylvania sends high schoolers, adults to hospital. A Spotsylvania County school 
bus driver and 1 1 students were transported to local hospitals for injuries after a vehicle 
struck the bus at Lake Anna Parkway and Courthouse Road March 23. 

Source: http://www.fredericksburg.com/news/local/spotsvlvania/school-bus-accident- 
in-spotsylvania-sends-high-schoolers-and-adults/article f90c0a0c-dl81-l Ie4-a5db- 
f3eebe2Q5el 1 .html 

20. March 23, WVEC 13 Hampton - (Virginia) Six students; driver of school bus injured 
in accident. The driver of a Suffolk Public School bus and six Nansemond Parkway 
Elementary School students were transported to a local hospital following an accident 
between the bus and another vehicle on the Nansemond Parkway March 23. 

Source: http://www.13newsnow.com/story/news/2015/03/23/suffolk-bus- 
accident/703 5 3624/ 

21. March 23, USA Today - (International) Troops notified their names are on Islamic 
State kill list. A Pentagon spokesperson reported March 23 that U.S. military units 
notified members whose names and addresses were included on a “kill list” allegedly 
created by the Islamic State Hacking Division, who claim to be sympathizers of the 
Islamic State terrorist group. Officials stated that the personal information of former 
and current military personnel was pulled from publicly available sources and was not 
attributed to a data breach. 

Source: http://www.usatodav.com/storv/news/nation/2015/03/23/pentagon-response- 
islamic-state-kill-list/70335810/ 

22. March 23, Tifton Gazette - (Georgia) 9 students injured in Ben Hill County bus 
wreck. Nine students were transported to an area hospital with injuries after a semi- 
truck rear-ended a Ben Hill County school bus on Highway 129 in Fitzgerald, Georgia, 
March 23. 

Source: http://www.tiftongazette.com/news/nine-students-injured-in-ben-hill-countv- 
bus^wreck/cuticle 70c I /T54~d 1 77- 1 1 e-i-9 Id 1 ■■a7edd5e36e69.html 

23. March 23, Walterboro Press and Standard - (South Carolina) School bus crash sends 
31 to medical center. A Colleton County School District bus veered off St. Peters 
Road, went into a ditch, and rolled on its side causing 30 middle school and high school 
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students and the bus driver to be transported to a local hospital for injuries March 23. 
Source: http://www.colletontoday.com/news/school-bus-crash-sends-to-medical-center- 
news-the-press/article 76d97ec8-dl6f-lle4-b2ac-bb2fe6dafa8a.html 

24. March 23, WJLA 7 Washington, D.C. - (Virginia) Bomb threat closes Lake 
Braddock Secondary in Fairfax County. Police cleared the scene after nothing 
suspicious was found at Lake Braddock Secondary School in Burke following a bomb 
threat that prompted the school’s closure March 23. 

Source: http://www.wila.com/articles/2015/03/bomb-threat-reported-at-lake-braddock- 
school-in-fairfax-county- 1 125 19.html 



For additional stories, see items 5 and 28 
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Emergency Services Sector 

25. March 23, FierceHomeIandSecurity.com - (National) DHS issues draft guidance for 
disaster information sharing following earthquake exercise. DHS’ Science and 
Technology Directorate published draft guidance containing Essential Elements of 
Information (EEIs) for information sharing in the event of an earthquake in Midwest 
and Southern States. The EEIs were created based on lessons learned from a June 2014 
planning exercise and instructs first responders on how to request and acquire mutual 
aid, among other recommendations. 

Source: http://www.fiercehornelandsecuritv.com/story/dhs-issues-draft-guidance- 
disaster- information-sharing-following-earthquake/201 5-03-23 



[Return to top ] 

Information Technology Sector 

26. March 24, Softpedia - (International) Jailbroken iPhones unlocked with software 
brute-force tool in 14 hours, tops. An iOS jailbreaker published a software library 
under the GNU General Public License called TransLock, that unlocks iOS devices in 
14 hours or less via brute-force by injecting itself into the app that manages the 
device’s home screen and setting return values in the “SBFDeviceLockController” 
class to “No”, allowing unlimited attempts and the ability to try a new PIN every five 
seconds. The tool only requires that the device be connected via USB. 

Source: http://news.softpedia.com/news/Jailbroken-iPhones-Unlocked-with-Software- 
Brute-Force-Tool-in- 1 4-Hours-Tops-47 6597 . shtml 

27. March 24, Softpedia - (International) Unauthorized certificates issued for several 
Google domains. Security engineers at Google reported that intermediate certificate 
authority at Egypt-based MCS Holdings caused certifications for several Google 
domains that are trusted by most operating systems (OS) and Web browsers to be 
issued without authentication, leaving users vulnerable to impersonation and secure 
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communication decryption via man-in-the-middle (MitM) attacks. Users of Google 
Chrome and Mozilla Firefox versions starting 33 are unaffected by the issue. 

Source: http://news.softpedia.com/news/Unauthorized-Certificates-Issued-for-Some- 
Google-Domains-476583.shtml 

28. March 24, Securityweek - (International) Air-gapped computers can communicate 
through heat: Researchers. Researchers at Israel’s Ben Gurion University 
demonstrated that it was possible to establish a bidirectional communication channel 
between two unconnected computers using heat and radio signals emitted from 
components such as the central processing unit (CPU) and graphics processing unit 
(GPU), allowing an attacker to use malware installed on each system to exfiltrate data 
from an air-gapped computer, dubbed BitWhisper. 

Source: http://www.securitvweek.com/air-gapped-computers-can-communicate- 
through-heat-researchers 

29. March 23, Softpedia - (International) Flash Player vulnerable to bug patched in 
2011 . Security researchers from Minded Security and Linkedln’s security division 
discovered that the latest versions of Adobe’s Flash Player Web browser plug-in are 
vulnerable to a same-origin bypass (SOP) flaw in the company’s Flex SDK compiler 
that was patched in 201 1, which could allow attackers to steal victims’ data via Same- 
Origin Request Forgery or perform actions on behalf of victims via Cross-site Request 
Forgery (CSRF) asking them to visit a malicious Web page. 

Source: http://news.softpedia.com/news/Flash-Plaver-Vulnerable-to-Bug-Patched-in- 
2011 -476543 .shtml 



30. March 23, Softpedia - (International) Twitch security breached, mandatory 

password reset in effect for all. The Twitch streaming service instituted mandatory 
password resets, disconnected all accounts from Twitter and YouTube, and emailed 
affected users after the company detected an authorized access attempt that could have 
compromised users’ in formation including dates of birth, time and Internet protocol 
(IP) address of last login, and limited information associated with credit cards. 

Source: http://news.softpedia.com/news/Twitch-Security-Breached-Mandatorv- 
Pass word-Reset-in-Effect-for- All-47 6558. shtml 



31. March 23, Securityweek - (International) DDoS attackers distracting security teams 
with shorter attacks: Corero Networks. Corero Network Security reported in their 
quarterly trends and analysis report that 96 percent of distributed denial-of- service 
(DDoS) attacks against its customers in the fourth quarter of 2014 were less than 30 
minutes in length and 79 percent used less than 5 gigabits per second (Gbps) of peak 
bandwidth, indicating that attacks were becoming more difficult to detect and were 
likely intended to partially saturate networks and distract security teams while leaving 
enough bandwidth for subsequent attacks to infiltrate networks and access sensitive 
information. 

Source: http://www.securitvweek.com/ddos-attackers-distracting-security-teams- 
shorter-attacks-corero-networks 
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For additional stories, see items 4 and 5 

Internet Alert Dashboard 

To report cyber infrastructure incidents or to request information, please contact US-CERT at soc@us-cert.gov or 
visit their Web site: http://www.us-cert.gov 

Information on IT information sharing and analysis can be found at the IT ISAC (Information Sharing and 
Analysis Center) Web site: http://www.it-isac.org 
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Communications Sector 

32. March 24, KVIA 7 El Paso - (New Mexico) Hostage threat at Las Cruces radio 
station building a “false alarm”. The Bravo Mic Communications building in Las 
Cruces which houses at least 2 radio stations and a marketing company was evacuated 
March 23 after a caller reportedly stated that he was armed and was going to take 
hostages inside the building. Authorities deemed the threat to be a false alarm and the 
building was cleared to reopen after about 4 hours. 

Source: http://www.kvia.com/news/l-person-in-standoff-with-police-at-las-cruces- 
radio-station-building/3 1 974644 

For another story, see item 26 
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Commercial Facilities Sector 

33. March 24, WSOC 9 Charlotte - (North Carolina) 3 dead in scaffolding collapse at 
downtown Raleigh high-rise. Three Associated Scaffolding subcontractors were killed 
and a fourth was seriously injured March 23 when a track snapped while the workers 
were dismantling a scaffold on the exterior of the under-construction Charter Square 
high rise in downtown Raleigh and the men fell about 200 feet to the ground. The 
North Carolina Department of Labor is investigating the incident. 

Source: http://www.wsoctv.com/news/news/report-3-dead-high-rise-scaffolding- 
collapse-ralei/nkcq5/ 

34. March 24, WGFL 53 High Springs - (Florida) Bomb threat at Ocala Mall. The 
Paddock Mall in Ocala was closed for more than 3 hours March 24 after an individual 
phoned the police and claimed to have planted 6 bombs at the mall that he planned to 
detonate. The mall was cleared to reopen after nothing suspicious was found. 

Source: http://www.mvgtn.tv/storv/28599450/bomb-threat-at-ocala-mall 

35. March 21, WPLG 10 Miami - (Florida) Opa-locka residents try to salvage what they 
can after massive fire. More than 100 residents were displaced from the Lakeview 
Apartments complex in Opa-locka, Florida, March 20 after a mattress caught fire and 
spread into a 3-alarm blaze that engulfed the structure. 
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Source: http://www.locallO.com/news/opalocka-residents-try-to-salvage-what-thev- 
can-after- massive-fire/3 1 943254 



For another story, see item 32 
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Dams Sector 



Nothing to report 
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Contact DHS 

To report physical infrastructure incidents or to request information, please contact the National Infrastructure 
Coordinating Center at nicc@hq.dhs.gov or (202) 282-9201. 

To report cyber infrastructure incidents or to request information, please contact US -CERT at soc@us-cert.gov or visit 
their Web page at www.us-cert.gov . 

Department of Homeland Security Disclaimer 

The DHS Daily Open Source Infrastructure Report is a non-commercial publication intended to educate and inform 
personnel engaged in infrastructure protection. Further reproduction or redistribution is subject to original copyright 
restrictions. DHS provides no warranty of ownership of the copyright, or accuracy with respect to the original source 
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